Telos Corporation released new findings from research conducted by independent research firm Vanson Bourne that examines how financial services are faring with the ever-increasing challenge of audit overload.
The study, which surveyed 200 U.S. IT security professionals in the financial services industry, revealed that nearly all (97%) financial institutions experience challenges when working on audits. While these challenges clearly impact the overall audit process, they also have implications for the IT security team members themselves. Just over three-quarters (78%) of surveyed IT security professionals in 2020 reported that they personally dread when their organization is audited. This figure has risen to 95% in 2021.
Key findings from the report include:
- Financial organizations spend an average of 71 working days each quarter responding to audit evidence requests, have an average of 13 different IT security compliance and privacy regulations with which they must comply, and have an average of 54 dedicated people who work on IT security compliance and/or privacy regulations.
- In 2021, 45% of organizations experienced employee sickness due to stress-related illness and 36% reported employee dissatisfaction, as compared to 34% and 19%, respectively, in 2020.
- While the majority (64%) of financial organizations use commercial governance, risk and compliance (GRC) solutions; IT GRC solutions; or IT risk management products, nearly half (47%) use a custom solution and over a third (37%) are still using spreadsheets to manage their compliance processes.
- 96% of IT security professionals believe that the tools their organization uses to collect security data could be improved in order to fully meet their needs – data aggregation and interpretation is something that 76% find particularly difficult.
“With the audit process continually increasing in complexity, the importance of tools that ease the process of aggregating and interpreting security data is more critical than ever,” said Rick Tracy, CSO and senior product manager at Telos. “With a new year quickly approaching, it’s time for organizations to rethink the current toolbox being used in their audit process by embracing automation, streamlining workflows and employing capabilities that bring the entire security compliance operation into perspective.”
With the average number of IT assets and cloud resources being monitored by financial organizations at any given time reaching just over two million, and with institutions running an average of 209 security control tests each month, of which only an average of 53% are automated, it is time to rethink the process.
“For organizations to streamline workflows and get ahead when it comes to audits, they need to implement processes that will accelerate audit activities and pull together massive amounts of compliance data in a concise and meaningful way,” said Tracy. “This will relieve the pressure on staff, free up necessary resources and ultimately make audits efficient and more accurate.”
For additional findings and to download the full report, visit https://www.telos.com/next-step/revisiting-the-harsh-reality-of-audit-fatigue-how-financial-services-are-faring-in-2021.
Source: https://www.securitymagazine.com/articles/96658-audit-dread-has-increased-from-78-in-2020-to-95-in-2021